CVE-2005-1842

Adobe Version Cue <1.3 - Local Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1842. PoCs published by vade79.

AI-analyzed exploit summary This exploit leverages a symlink attack on Adobe Version Cue's VCNative program to overwrite /etc/crontab, which then modifies /etc/sudoers to grant root access via sudo. It requires cron and sudo to be present on the system.

Description

VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a symlink attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by vade79 · perllocalosx
https://www.exploit-db.com/exploits/1185

This exploit leverages a symlink attack on Adobe Version Cue's VCNative program to overwrite /etc/crontab, which then modifies /etc/sudoers to grant root access via sudo. It requires cron and sudo to be present on the system.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Adobe Version Cue (VCNative) on macOS
No auth needed
Prerequisites: Adobe Version Cue installed · cron running · sudo installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14638
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/techdocs/327129.html
Various Sources third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=297&type=vulnerabilities
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014776
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16541

Scores

EPSS 0.0091
EPSS Percentile 55.4%

Details

Status published
Products (2)
adobe/version_cue 1.0
adobe/version_cue 1.0.1
Published Aug 24, 2005
Tracked Since Feb 18, 2026